export default defineEventHandler((event) => {
	setResponseHeader(event, 'Access-Control-Allow-Origin', '*');
	setResponseHeader(
		event,
		'Access-Control-Allow-Methods',
		'GET, POST, PUT, DELETE, PATCH, OPTIONS'
	);
	setResponseHeader(event, 'Access-Control-Allow-Headers', '*');
	setResponseHeader(event, 'Access-Control-Max-Age', 3600);
	setResponseHeader(event, 'Content-Type', 'application/json');
	setResponseHeader(event, 'Access-Control-Allow-Credentials', 'true'); // 允许携带 Cookie
});
